When a cyberattack hits critical infrastructure, governments have playbooks. When a nuclear threat emerges, there are verification regimes and coordination channels. For AI, almost none of this exists.
No US agency can verify where the most powerful AI chips are, what’s running on them, or whether safety commitments are being honored. Three jurisdictions (California, New York and the EU) now require AI incident reporting, but reporting is not response: no federal plan governs what happens when a system crosses a dangerous capability threshold.
We work on two priorities. First, emergency preparedness. We work with federal officials, Congressional staff, state agencies, and their transatlantic counterparts to stress-test how existing AI laws handle national security crises and build incident response capacity.
Second, verification to check commitments – trust, but verify. We connect the people building tools like chip tracking, energy grid monitoring, and cryptographic agent identification with the policymakers and funders who need them, and build transatlantic cooperation so allies can verify together.
We also convene the Athens Roundtable on AI and the Rule of Law, now in its eight edition, to build the coordination infrastructure these threats require.
Related resources
AI Incidents Are Rising. It’s Time for the United States to Build Playbooks for When AI Fails.
AI Incidents Are Rising. It’s Time for the United States to Build Playbooks for When AI Fails.
Building on the White House AI Action Plan's mandate for federal incident response frameworks, we analyze recent AI incidents, identify...


